SQL Injection Vulnerability in Linlinjava Litemall 1.8.0 Allows Remote Attacker to Obtain Sensitive Information
CVE-2024-46382
7.5HIGH
What is CVE-2024-46382?
A SQL injection vulnerability exists in the Linlinjava Litemall version 1.8.0, allowing remote attackers to exploit parameters such as goodsId, goodsSn, and name within the AdminGoodscontroller.java file. This provides malicious actors the ability to retrieve sensitive information, raising concerns about data confidentiality and the potential for further exploits if not addressed. Security best practices and immediate remediation are essential to protect against possible data breaches.
